7e5c3453 tinklas (#1259): `tinklas connect` gets its answer — tinklasd sent a join's result to subscribed clients only and the CLI never subscribes; it now an
fec7ebf5 i915 gen9 (#1236, #1235): 2D acceleration ON by default on gen9/gen9.5 (off: i915nogen9), with BCS engine reset + retry and S3 resume rebuild; CFL/WHL/
fab2f794 brcmfmac (#1194): the BCM4350 JOINS on the MacBook10,1 (k2150 = 8dd3da9e, DHCP on wlan0) — and the re-join that then killed the firmware is fixed: li
8dd3da9e brcmfmac (#1194, k2148): commonring_config zeroed the ARM's reset vector (TCM word 0) twice per common ring — upstream calls the index-write callback
f77bb52c brcmfmac (#1194): k2145's probe panic fixed (a ring_info pointer read back all-ones passed a 32-bit wrap-around range test; every BAR2 access is now bo
2ed9d509 dhcp (#1257): the kernel DHCP client renews at T1 (unicast), rebinds at T2 (broadcast), drops the address and re-DISCOVERs on expiry or NAK, and asks f
9a2617be backlight (#1255): arch64audit ulong — the sysfs stores and the writev join return int, not long
47981689 brcmfmac (#1194): the host never stores into the dead index region (source audit), so the store ORDER is made comparable with Linux (brcmfmmiolog=1 + t
fc0549bd tinklas (#1253): /etc/resolv.conf follows the DHCP lease — tinklasd rewrites it atomically on every lease, static change and interface switch, from a
6ca445c2 brcmfmac (#1194): alignment FALSIFIED on k2135, where the first damage is the ring-index region (0x23b68c..) within ~2 ms of the first TX post; txsync 
ef288deb brcmfmac (#1194): the Linux TCM reference is diffed against the port (the flow-ring ring_mem slots are firmware-written; the layout matches); brcmfdmaa
e474b767 backlight (#1255): writev into /sys is one value (echo N > brightness returned EINVAL while applying N), the MacBook10,1 caps-lock LED, and an ASLE log
0495b066 brcmfmac (#1194): address window FALSIFIED on k2129 and the overwrite is chip-internal (no PCIe DMA); tcmsnap prints the chip's control structures, too
b21d3c06 backlight (#1255): ACPI video + the i915 ASLE half for screen brightness, applespi's spi::kbd_backlight, a backlight/LED class, and System Preferences 
7ed1ecc2 brcmfmac (#1194): brcmfdmahigh=1 moves every brcmf DMA buffer out of the chip's backplane view of host memory (0x08000000-0x0fffffff, where all of ours
a4786468 brcmfmac (#1194): MPS FALSIFIED on k2120, whose capture caught an h2d0 host-read fetch of the newest control item with address high word 0; brcmftxprob
88a00b0b brcmfmac (#1194): Linux joins on this MacBook10,1 with our firmware, so the bug is ours; print the radio's and its root port's PCIe DevCtl/LnkCtl/DevCt
7f91245b brcmfmac (#1194): the death timeline ran only on a bus still marked up, so k2115 (death found first by an ioctl waiter) got none — it now runs first 
92ef4de3 brcmfmac (#1194): alignment FALSIFIED on k2113, whose instruments show the death is an upward all-ones DMA overwrite from 0x1e807c; brcmftxprobe now ca
e438f720 brcmfmac (#1194): brcmftxpad=N (word-aligned TX payload — the one difference from Linux/FreeBSD a research pass found), a chip post-mortem in FIRMWAR
f5a235bb keyboard (#1251): keys typed into a desktop window no longer run in the console's root shell — a readable /dev/kbd takes a keyboard claim; dualgui64_
dbdacf38 brcmfmac (#1194): ASPM FALSIFIED on k2108; the "control-submit backlog" is a stale cached H2D rptr, not a measurement — the FIRMWARE GONE report now 
fe4a4bcd installer, agpt, sysfs (#1248): the graphical installer installs ALONGSIDE macOS/Windows — prepared pair, free space, or guidance; agpt probe/add/slo
7d4fb662 brcmfmac (#1194): mpc FALSIFIED on k2106 and the host-store trace clears the host; FIRMWARE GONE now dumps flow-ring item 0 and the outstanding TX buff
e9be55e1 brcmfmac (#1194): power save FALSIFIED on k2104; a declined sweep no longer prints "scan complete" (an instrument that could not fail); FIRMWARE GONE n
658fb72d brcmfmac (#1194): the EAPOL-ordering hypothesis is FALSIFIED on k2101 (the firmware still dies ~10 ms after the first TX post); power save becomes the 
aa6d2bb5 mac80211 (#1194): a FullMAC radio's EAPOL that arrives before the firmware's join verdict is held and replayed after it, as wpa_supplicant's pending_ea
bd1aaf43 nvme, limine: the per-I/O NVMe trace is opt-in (nvmetrace) and a timeout names its command; pitprobe off the MacBook12 netlog entry
4873ca7c macdual64_gate, #1246: the block cache was NOT the second cause — measured, and the nodrop arm deleted because it could not fail
f1b2b004 brcmfmac (#1194): the BCM4350 firmware dies on the first TX post of a join — the driver now says so once and parks the bus instead of flooding the ma
1f03af20 nvme, blockdev, installer: an NVMe FLUSH at every durability point, and a VERIFY that reads the device (#1246)
31b15fa1 audio capture (#1197, #947): the MacBook10,1 had no microphone because HDA connection lists were decoded as 4-bit entries; capture source chosen built-
36f7be9e fasadas HiDPI (#595): a backing scale factor end to end — the MacBook10,1's 2880x1800 comes up as a 1440x900-point desktop drawn at 2x; 1x machines b
c16b0b78 wifi (#1194): the MacBook10,1's "0 networks" was the Wi-Fi switch, not the scan — and a FullMAC sweep's 2.5 s exposed three sweep races in mac80211; 
9515296f i915 gen9 (#1196 M1): a blitter engine for Skylake/Kaby Lake — 64-bit GGTT, gen9 forcewake, private PAT, aliasing PPGTT, execlists on the BCS — as 
3eec511b installer, nvme: ainstall --dualboot for the MacBook10,1's 4Kn SSD, agpt reads 4Kn tables, and the NVMe timeout was 6 ms (#1230, #1231)
ff3dda45 clock: x86 timekeeping the Linux way — CPUID 0x15, HPET, TSC clocksource, LAPIC tick, no PIT (#1228)
2c845f0f limine: a MacBook12 desktop entry (33) — the bring-up entries carry debug and never start Fasadas
26f0c1f5 sched, pit: the sleep trace is off by default, and the PIT verdict is a rate — from the MacBook10,1's first boot of the fixed kernel (#1226)
fe5d6205 pit: pit_itss_report() returns an int, not the register as a long (#1226)
ba68c9ff limine: a MacBook12 `pitungate` experiment entry, and the entry table in MACBOOK12.md corrected to 27-32 (#1226)
2fbd93f9 fb: the console scanout gets its own PAT write-combining mapping — the direct map was uncached on the MacBook10,1, 244 ms per scrolled line (#1227)
c46092c6 clock: the MacBook10,1's firmware gates the 8254 from _INI; the LAPIC takes the tick over, on the BSP only (#1226)
15696e0a pit: one tick-counter update, shared and without inline asm (#1226)
b99f0b91 pit: the LAPIC fallback advanced the counter but never ran the tick's work (#1226)
258897c7 lapic: the LINT0 drop restored a snapshot instead of the state, leaving the entry masked (#1226)
d4871b4c pit: drop an unacknowledged ExtINT on LINT0, and drive the fallback per LAPIC tick (#1226)
7dbcb615 pit: the 8254's own status, an escalation ladder, and a LAPIC tick fallback when the PIT stops (#1226)
5d7dc9f6 keyboard: the kbdecho injector was created but never scheduled, so its gate could not pass (#966)
9e2e5824 ioapic: the census took a physical address in a uint32_t, which arch64audit gates
dd4d253e pit: the wedge recovery announced its own input twice, so it could not report a failure (#1226)
825a9a4f pit: the probe was stopping the timer it was written to diagnose (#1226)
02369a45 squashfs: take the backing read out of sqfs_sect_lock (#1226)
867c76d7 pit: `pitprobe`, the instrument for a PIT that has stopped (#1226)
f3ee3b52 console: a key typed at the kernel console now reaches the shell (#966)
04f60961 keyboard: the "first scancode" comment named one source of three
f7f01509 limine: drop resolution= from the MacBook12 entries - conscale= is enough (#1224)
60778acc console: conscale=N - the framebuffer console's glyph scale was unreachable (#1224)
d7acb8ad traps: restore the NMI watchdog's pre-scheduler gate - measured on the MacBook10,1 (#1219)
df5d490f traps: remove the watchdog's pre-scheduler gate - it was right all along (#1219)
86db4e2f fb: hold the shadow free off while the sweep reads it (#1222)
298b7a3a fb: set fb_flush_live after the first flush, not before the sleep (#1219)
c4858bcd audit: four defects in the #1219 work, and one correction to how it was read
0b3c37c4 printk: bound the emit ring's overflow wait, and audit the premise (#1219)
7bb2d9fa sched: the tick selftest answered, and is removed (#1219)
9e22c87f sched: the tick selftest is a bounded spin, not a bare hlt (#1219)
1d3ff2b7 sched: ask the LAPIC tick to prove it arrives, in words (#1219)
3a43c132 lapic: make the timer report its own registers at start (#1219)
dd2bcb37 sched/traps: hb on the sleep trace, and a watchdog that arms on a dispatcher (#1219)
9359b031 fb: keep the console drawing until the flusher has actually run (#1219)
bb1a44b4 sched: bound the sleep spin arms on the TSC, not on a counter the caller froze (#1219)
78cfd09d xhci: stop instead of walking into the firmware's SMM trap (#1219)
73bbb68b revert: the framebuffer speculation, and what the frame walk actually found (#1219)
4179297e nmi: walk rbp for the wedged caller, because the stack scan was lying (#1219)
cbac9b0a fb: find the hole by timing EVERY chunk, not by probing offset 0 (#1219)
ce7b162c fb: uint64_t for the probe rate, not unsigned long (arch64audit ulong)
4317288d audit: annotate the three u32addr findings the #1219 work added
d6ef9981 fb: probe the shadow->VRAM push before trusting it, and survive when it is unusable (#1219)
45047829 fb: bound the deferred VRAM push in time, and make it resumable (#1219)
f250a35b nmi: the watchdog's census names the CALLER of the wedged instruction (#1219)
a5316fbe sched: a stage marker inside sched_switch_out's interrupts-off window, plus the two traces that found the wedge (#1219)
fa901784 boot: a MacBook12 entry that SURVIVES the slim build, for the #1219 wedge test
7c2354bc boot: arm the NMI watchdog on the MacBook12 entries (#1219)
e623411b nvme: bound the command wait on a clock IRQ0 cannot stop, and name the I/O before waiting on it (#1218, #1217)
0b72d470 net: Realtek USB Ethernet (r8152) — RTL8152 to RTL8157, every row of Linux's table, the owner's 0bda:8156 included (#1199 part 2)
87892f79 treelint green again (arch64audit, waitlint) + live root from a USB stick, no CD (#1205)
d92c7e29 kernel: the ACPI power button (button.c port) — a short press shuts down in order and the next press still works; acpica64_gate 66/66 (#1207)
cd8a446a kernel: ACPICA consumers — applespi SIEN/_DSM, an EC driver, the Control-Method battery/AC/lid; MacBook10,1 switch-over proven on its own tables (#12
46e845be kernel: ACPICA R2025_04_04 is the AML interpreter — vendored unchanged, Linux OSL semantics, Linux init order, acpica64_gate 44/44 (#125)
56ece565 brcmfmac (#1194): firmware-up wait as a pit_mono_ns deadline, elapsed time measured — the counted-for rewrite charged 50 ms per sleep beside sleep_ms
e7c37c1b brcmfmac (#1194, epic #1192): Broadcom FullMAC PCIe WiFi for the MacBook10,1's BCM4350 — chip attach, firmware download, msgbuf rings, fwil/fweh, esc
f44e775c usb: devices behind hubs on xHCI (#1198) + USB Ethernet core, cdc_ether, cdc_ncm (#1199 part 1)
82123a46 live ISO: a MacBook10,1 bring-up entry — squashfs, debug, noefi, noswap; appended last so no gate's entry index moves (#1192)
a74869d5 kernel: Intel LPSS SPI host + Apple SPI keyboard/trackpad protocol (#1182, epic #1168)
b7b9c83f MacBook10,1 (#1192): NVMe finds Apple 106b:2003 by ID and drives 4096-byte-LBA namespaces, GPT/MBR read in logical blocks, six drivers stop truncating 
53d667f3 evdev (#1170): stated 64-bit types — int64_t ioctl returns and input_event time fields, size_t byte counts — clearing phase 1's 17 arch64audit viol
